Repository navigation

#

etw-bypass

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Rust
223
6 个月前

Two in one, patch lifetime powershell console, no more etw and amsi!

Go
96
4 个月前

A WIP shellcode loader tool which bypasses AV/EDR, coded in C++, and equipped with a minimal builder.

C++
63
7 天前

Generator of https://github.com/TheWover/donut in pure Go. supports compression, AMSI/WLDP/ETW bypass, etc.

Go
60
2 年前

A proof of concept AMSI & ETW bypass using trampolines for hooking and modifying execution flow

C
15
2 个月前

code snippet provided demonstrates how to patch the EtwEventWrite function in the ntdll.dll library on Windows using CGO (C Go).

Go
9
4 个月前

ETW Bypass by patching main ETW internal function

C
3
3 个月前

Forge your payloads into undetectable forces. Engineered for stability, power, and silent operation.

1
1 个月前

Undetected (at the time of writing this) ETW and Amsi Patcher in C#

C#
1
1 天前

Remove ETW providers from session &ETW session hijack

C++
0
5 个月前

Nyx is a lightweight scripting language that prioritizes simplicity and ease of use. 🌟 With Nyx, you can quickly run scripts and explore creative coding possibilities. 🐙

C++
0
1 个月前

Diabellstar is a Rust-based tool that performs ETW bypass by patching the NtTraceEvent function in ntdll.dll

Rust
0
1 个月前

Clean forensic traces on Linux, macOS, and Windows with Nyx. This alpha tool helps maintain privacy by removing various system artifacts. 🐙💻

0
25 天前